U.S. healthcare IT company CareCloud now says a breach from earlier this year hit more than 3.7 million people. In a report to the U.S. Department of Health and Human Services, the company listed 3,756,469 individuals as affected.
CareCloud is publicly traded. It sells electronic health records, medical billing, practice management, and revenue-cycle services. You do not hire them. Your doctor’s office does. That is why a pile of regular people are about to get a letter from a company they have never heard of.
The March attack on CareCloud’s AWS environment
CareCloud first disclosed the incident in March through a filing with the U.S. Securities and Exchange Commission. The attack caused an 8-hour network disruption on its platform and cut access to one of its databases. The firm said then that the compromised environment contained patient data.
The later investigation pinned down the window. Between March 10 and March 16, 2026, an unauthorized third party accessed one of CareCloud’s AWS environments and claimed to have exfiltrated data from databases inside that environment. That is the language in the sample notification letter filed with authorities.
A week inside an AWS environment holding patient data is not a small glitch. That is a walk-through.
What the company will not say about the stolen data
The sample letter confirms full names were exposed. Beyond that, CareCloud does not spell out the rest. No clear list of Social Security numbers, dates of birth, diagnoses, or insurance details in the public notice. When a healthtech vendor stays vague, assume the useful stuff walked out too. Names alone are not why you get a year of identity monitoring.
No ransomware group or data extortion gang has taken credit for the attack. That does not make the data safer. It just means nobody is waving it around yet.
Letters started going out in July
CareCloud began distributing data breach notifications on July 25. People who get the letter are offered 12 or 24 months of identity protection through IDX, redeemable until December 17, 2026. Use it. It is the only concrete thing they are handing back after losing control of the environment.
Because CareCloud has no direct relationship with patients, a lot of those 3.7 million people will see this name for the first time on an envelope. That is the healthcare IT model in a nutshell. Your records sit with vendors you never chose, in cloud setups you never approved, until something breaks.
What this means if you or your family might be in the pile
This is the part that matters for normal people. You cannot un-steal a database. You can stop the follow-on damage.
- If a CareCloud notice shows up, enroll in the IDX coverage before December 17, 2026.
- Treat any follow-up email, text, or call about this breach as a likely phishing attempt. Real notices go out on paper first. Attackers love a fresh breach story.
- Watch insurance statements and Explanation of Benefits for visits or claims you did not make.
- If the letter stays vague about what was taken, freeze your credit. Vague usually means they do not want to print the ugly inventory.
- Ask your clinic which billing and EHR vendors handle your file. You have a right to know who is holding it.
Healthcare vendors keep stuffing patient data into cloud environments and then acting shocked when someone gets in. This one ran March 10 through March 16. Eight hours of downtime. 3,756,469 people. And they still will not give a full accounting of what left besides names.
Stay sharp. The letter is not closure. It is the opening of the phishing season that always follows these messes.
Primary Source: https://www.bleepingcomputer.com/news/security/healthtech-firm-carecloud-data-breach-impacts-37-million-patients/
